AWS mgn: Update manual MGN connector IAM policy examples and trust condition
Summary
Replaces placeholder tokens with concrete example values and changes the trust relationship condition operator from StringLike to ArnLike for aws:SourceArn.
Security assessment
Same IAM trust policy correction as the console doc: aws:SourceArn now uses ArnLike, the correct operator for ARN matching, improving the cross-account role assumption condition.
Evidence
+ "ArnLike": {
Diff
diff --git a/mgn/latest/ug/create-permissions-manually.md b/mgn/latest/ug/create-permissions-manually.md index 39dea5f80..e6b6375fb 100644 --- a//mgn/latest/ug/create-permissions-manually.md +++ b//mgn/latest/ug/create-permissions-manually.md @@ -25 +25 @@ To create the role: - 1. After replacing **ACCOUNT-ID** with your account number, and **AWS_REGION** with the connector region, create a policy from the following JSON: + 1. In the following JSON, replace the example account ID `111122223333` with your account number, and the example Region `us-east-1` with the connector Region. Then, create a policy from the JSON: @@ -32 +32 @@ To create the role: - "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:*", + "Resource": "arn:aws:mgn:us-east-1:111122223333:*", @@ -37 +37 @@ To create the role: - "Resource": "arn:aws:mgn:AWS_REGION:ACCOUNT-ID:connector/*", + "Resource": "arn:aws:mgn:us-east-1:111122223333:connector/*", @@ -47 +47 @@ To create the role: - "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_ACCOUNT-ID", + "Resource": "arn:aws:iam::*:role/AWSApplicationMigrationConnectorSharingRole_111122223333", @@ -57 +57 @@ To create the role: - "Resource": "arn:aws:secretsmanager:AWS_REGION:ACCOUNT-ID:secret:*", + "Resource": "arn:aws:secretsmanager:us-east-1:111122223333:secret:*", @@ -63,2 +63,2 @@ To create the role: - "arn:aws:s3:::aws-application-migration-service-AWS_REGION/latest/source-automation-client/linux/ssaf-client/ssaf_client", - "arn:aws:s3:::amazon-ssm-AWS_REGION/*" + "arn:aws:s3:::aws-application-migration-service-us-east-1/latest/source-automation-client/linux/ssaf-client/ssaf_client", + "arn:aws:s3:::amazon-ssm-us-east-1/*" @@ -155 +155 @@ To create the role: - "aws:SourceAccount": "management-account-id" + "aws:SourceAccount": "111122223333" @@ -157,2 +157,2 @@ To create the role: - "StringLike": { - "aws:SourceArn": "arn:aws:mgn:*:management-account-id:*" + "ArnLike": { + "aws:SourceArn": "arn:aws:mgn:*:111122223333:*" @@ -165 +165 @@ To create the role: - "AWS": "arn:aws:iam::management-account-id:role/AWSApplicationMigrationConnectorManagementRole" + "AWS": "arn:aws:iam::111122223333:role/AWSApplicationMigrationConnectorManagementRole"